Splatt Forum Post Icon HTML Injection Vulnerability
BID:8198
Info
Splatt Forum Post Icon HTML Injection Vulnerability
| Bugtraq ID: | 8198 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2003 12:00AM |
| Updated: | Jul 15 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Lethalman <[email protected]>. |
| Vulnerable: |
Splatt Forum 4.1.1 Splatt Forum 4.0 Splatt Forum 3.2 Splatt Forum 3.1 Splatt Forum 3.0 |
| Not Vulnerable: | |
Discussion
Splatt Forum Post Icon HTML Injection Vulnerability
Splatt Forum has been reported prone to a HTML injection vulnerability.
An attacker may save a Splatt Forum post form, and modify it so that the post icon value contains arbitrary attacker supplied HTML code. As a result, a malicious user may have the ability to submit a post to the site containing embedded script code. This code would be executed by a user's browser in the context of the vulnerable site.
Splatt Forum has been reported prone to a HTML injection vulnerability.
An attacker may save a Splatt Forum post form, and modify it so that the post icon value contains arbitrary attacker supplied HTML code. As a result, a malicious user may have the ability to submit a post to the site containing embedded script code. This code would be executed by a user's browser in the context of the vulnerable site.
Exploit / POC
Splatt Forum Post Icon HTML Injection Vulnerability
The following proof of concept exploit has been provided:
The following proof of concept exploit has been provided:
Solution / Fix
Splatt Forum Post Icon HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Splatt Forum Post Icon HTML Injection Vulnerability
References:
References:
- Splatt Homepage (Splatt)
- Splatt Forum html injection code in post icon (Lethalman
)